2 options:1) use Dnsmasq instead of unbound2) unbound dns > query forwarding > check "use system nameservers"
Quote from: Dslgeek on February 12, 2023, 08:41:58 am2 options:1) use Dnsmasq instead of unbound2) unbound dns > query forwarding > check "use system nameservers"Option 2 worked, but now I'm leaking my internal ip adresse in the WebRTC detection.EDIT: Seems to only be on my android phone, so maybe not an OPNsense issue.
I've tried to make a Port forward rule (see attached screenshot), but I'm not sure I'm doing it right.It doesn't make a difference on my phone, the lan ip is still shown.
Quote from: REH on February 12, 2023, 02:29:38 pmI've tried to make a Port forward rule (see attached screenshot), but I'm not sure I'm doing it right.It doesn't make a difference on my phone, the lan ip is still shown.Change the destination to anyFirewall: NAT: Port Forward, Create new ruleInterface: Home (assume your wireless access point is in Home interface)TCP/IP Version: IPv4Protocol: UDPDestination: anyDestination port range: DNS to DNSRedirect target IP: 127.0.0.1Redirect target port: 53If that still doesn't work, your phone is probably using DNS over TLS or DNS over HTTP.Which cannot be redirected.
If you're using Quad9, their main benefit is that they fully support DNS over TLS to give you encrypted DNS and also take advantage of their malware blocking. By default, just specifying their DNS server in general settings will not use any of this benefit.